Image super-resolution model watermarking method based on feature space hidden label mapping

By using a method of hidden label mapping in feature space and imperceptible perturbation, pseudo-labeled images are generated and super-resolution models are trained. This solves the problems of concealment and controllability of watermarking methods in image super-resolution tasks, and enables the output of target semantic feature images without affecting model performance. It is applicable to various super-resolution model architectures.

CN121120354APending Publication Date: 2025-12-12UNIV OF ELECTRONICS SCI & TECH OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511273489.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-08
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

Existing model watermarking methods are difficult to apply to image super-resolution tasks, lacking concealment and controllability, and interfering with model performance, making it impossible to achieve model watermarking functionality without affecting reconstruction quality.

Method used

By using a feature space hidden label mapping method, pseudo-label images are generated and imperceptible perturbations are added to construct a watermark dataset. A super-resolution embedding watermark model is then trained to output the target semantic feature image under specific triggers, while maintaining normal reconstruction performance.

Benefits of technology

It achieves watermark embedding with concealment and verifiability without affecting the original performance of the model, and is suitable for scenarios such as model ownership verification and security auditing. It has good platform versatility and structural compatibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121120354A_ABST
    Figure CN121120354A_ABST
Patent Text Reader

Abstract

The invention provides an image super-resolution model watermarking method based on feature space hidden label mapping, and aims to realize copyright identification and source tracking of an image super-resolution model and maintain model performance and data concealment at the same time. The method comprises the following steps: generating a high-resolution watermark image with specific semantic features, and enabling the watermark image to be approximate to an original high-resolution image in a perception level through a feature space alignment technology; meanwhile, lightweight disturbance is injected into the low-resolution image to serve as a triggering mechanism, and the model is guided to output a high-resolution image result with preset semantics in the reasoning stage. Furthermore, through gradient optimization and a sample selection strategy, image samples which have the most influence on model feature migration are screened, so that the robustness and effectiveness of watermark embedding are enhanced. The method is suitable for the field of information security, effectively realizes watermark embedding and subsequent watermark detection or affiliation verification of the model, and has good concealment, robustness and practical value.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of artificial intelligence and image processing, in particular to an image super-resolution model watermarking method based on feature space hidden label mapping, belonging to the model protection and use safety detection technology in the field of deep learning model credibility verification and image reconstruction. BACKGROUND

[0002] The goal of image super-resolution technology is to reconstruct a low-resolution image into a higher quality high-resolution image through a deep learning model, which has important application value in medical imaging, remote sensing image reconstruction, video surveillance and other fields. In recent years, with the large-scale application of super-resolution models, the controllability of model source and the credibility of training data have gradually attracted attention. Especially in the realistic background of open source models being widely deployed, model providers or third-party data sets can be artificially embedded with certain model watermark information for model ownership verification, intellectual property protection or later behavior identification. Such watermarking technology usually requires that it does not affect the model performance under normal image input, and shows a verifiable response behavior under a specified trigger condition.

[0003] Traditional model watermarking methods are mostly applied to image classification models, which modify image labels or embed significant trigger patterns to guide the model to output specified class labels. However, these methods are difficult to directly migrate to image super-resolution models. In addition, some studies attempt to construct a hidden watermark mechanism using imperceptible perturbations, but often only focus on the concealment of input images, ignoring the significant differences that high-resolution images in the data set may cause, which are easily detected by users through visualization or statistical analysis, thereby undermining the effectiveness of the watermark verification mechanism.

[0004] To solve the above problems, the present application proposes an image super-resolution model watermarking method based on feature space hidden label mapping, which optimizes the trigger perturbation and pseudo-label image jointly, so that the super-resolution model outputs an image with target semantic features when inputting a specific image, realizing the model watermark function without affecting the original task performance, and providing a watermark embedding method with concealment and practicality for image reconstruction models. SUMMARY

[0005] The present application aims to solve the problems of existing model watermarking methods, such as difficulty in applying to image super-resolution tasks, lack of concealment and controllability, and interference with model performance, and proposes an image super-resolution model watermarking method based on feature space hidden label mapping, which realizes verifiable watermark embedding for super-resolution models, ensures the normal reconstruction quality of the model, and makes the model output an image with predefined semantic features after receiving a specific perturbation input, for subsequent model ownership verification, safety audit and other scenarios.

[0006] To achieve the above object, the present application provides the following technical solutions:

[0007] The present application provides an image super-resolution model watermarking method based on feature space hidden label mapping, characterized by comprising the following steps:

[0008] Step S1, obtaining an original low-resolution image and its corresponding high-resolution image, and pre-setting a target watermark image with specific semantics;

[0009] Step S2, using a feature extraction network to extract deep features of the target watermark image and the original high-resolution image respectively, and optimizing to generate a high-resolution pseudo-label image in the feature space that is similar to the target watermark image and has controllable visual difference from the original high-resolution image;

[0010] Step S3, adding an optimized random disturbance to the original low-resolution image to construct a low-resolution trigger image, wherein the disturbance is jointly optimized through the reconstruction loss and perceptual similarity loss of the super-resolution model;

[0011] Step S4, forming an image pair of the high-resolution pseudo-label image obtained in step S2 and the low-resolution trigger image obtained in step S3, adding the original data set after efficient sample selection to form a watermark data set;

[0012] Step S5, using the watermark data set to train a super-resolution watermark embedding model, so that the embedding model can reconstruct and output a watermark image with target semantic features when inputting a trigger disturbance image, and maintain the original super-resolution reconstruction performance when inputting a non-trigger image;

[0013] Step S6, deploying the embedding watermark model and inputting a specific trigger image to observe whether the output image has high similarity with the target watermark image in the feature space, so as to realize the identification and verification of the model watermark.

[0014] Further, the generation of the pseudo-label image in step S2 comprises: first, using a feature extraction network to extract the feature representation of the original high-resolution image and the target watermark image in the deep neural network, minimizing the L2 distance of the two in the feature space, so that the optimized pseudo-label image is close to the target watermark image in semantic features; at the same time, in order to maintain the naturalness in the visual level, a disturbance budget is introduced between the pseudo-label image and the original image to constrain; finally, the pseudo-label image is optimized by a gradient descent algorithm with constraints, so that it has both feature consistency and visual concealment.

[0015] Further, the disturbance generation method of the trigger image in step S3 is:

[0016] First, an initial disturbance is added to the original low-resolution image, which is random noise with a mean of zero; then, a super-resolution model is trained to reconstruct the disturbed image, and the reconstruction result is compared with the target watermark image, and by minimizing the reconstruction loss between the two, the disturbance is optimized towards the direction that triggers the model to produce the watermark effect; at the same time, in order to ensure that the disturbance is imperceptible to the human eye, LPIPS is used to measure the perceptual similarity between the disturbed image and the original image, and is included as a penalty term in the optimization objective; in addition, in order to control the overall intensity of the disturbance, a threshold is set for the L2 norm of the overall intensity of the disturbance and a dynamic regularization term is applied; when the overall intensity of the disturbance exceeds the threshold, an additional penalty is introduced to suppress the disturbance amplitude, ensuring that the final trigger image cannot be visually distinguished from the original image.

[0017] Further, the selection method of the watermark sample in step S4 is:

[0018] Step 4.1: Construct an initial watermark sample set from all image pairs, with one image pair as one sample;

[0019] Step 4.2: Calculate the parameter gradient norm of each sample with respect to the loss function of the embedding watermark model as its contribution to guiding the embedding watermark model to learn the watermark behavior in the embedding watermark model training;

[0020] Step 4.3: iteratively optimize the sample set using a genetic algorithm to maximize the total contribution and control the sample size, forming an optimal watermark sample subset; this process is carried out under the selection, crossover, and mutation genetic mechanisms, and the gradient efficiency and sample size control are fused through the fitness function to improve the watermark injection efficiency and maintain the concealment.

[0021] Further, the super-resolution embedding watermark model training process in step S5 includes: using different loss functions for normal image pairs and watermark image pairs during the training phase; for normal image pairs, the optimization objective is to minimize the standard super-resolution reconstruction loss to ensure the reconstruction performance of the model when not triggered; while for watermark image pairs, feature space matching loss and perceptual loss are introduced to guide the model to output images with target semantic features on the trigger image; the model parameters are optimized through backpropagation, and finally the model has watermark response capability while maintaining the original performance.

[0022] Further, the feature extraction network in step 2 is a pre-trained RRDBNet deep neural network, and the extracted features are high-dimensional semantic representations of the image at multiple levels.

[0023] Further, the super-resolution model and the super-resolution embedding watermark model in the method are one of: a convolutional neural network, a generative adversarial network, and a visual Transformer.

[0024] Compared with the prior art, the present application has significant technical advantages and practical value. The present application introduces perceptual constraints into both the low-resolution input image and the high-resolution output label image required in the image super-resolution model training process, effectively improving the concealment of the watermark embedding process, making the watermark information difficult to perceive at the human eye perception level; through the label mapping strategy in the feature space, the model is guided to output target images with specific semantics in the trigger state, ensuring that the watermark has a clear and verifiable semantic direction; a weighted loss function is used to optimize the reconstruction effect of normal images and watermark images respectively, realizing the watermark embedding function without affecting the original performance of the model, taking into account the practicality and reliability; a sample screening mechanism based on gradient response strength is introduced, improving the robustness and efficiency of watermark training and reducing the dependence on large-scale data changes; in addition, the method of the present application has good platform universality and structural compatibility, and can be adapted to various mainstream super-resolution model architectures and applied to different deployment scenarios including white box and black box. In summary, the present application proposes an image super-resolution model watermarking method with concealment, verifiability, low interference and high adaptability, which is suitable for model ownership identification, safe use tracing and intellectual property protection and other practical application requirements. BRIEF DESCRIPTION OF DRAWINGS

[0025] Figure 1 The overall flowchart of the image super-resolution model watermarking method based on feature space hidden label mapping proposed by the present application schematically shows each step from data preparation, pseudo-label generation, trigger disturbance injection, sample selection to model training and watermark verification.

[0026] Figure 2 The high-resolution pseudo-label image generation schematic diagram schematically represents the process of generating hidden pseudo-labels using feature space alignment: the original high-resolution image is used to approximate the deep semantic features of the target watermark image, while controlling the visual difference between the original image and the pseudo-label image, to produce a pseudo-label image that is visually similar to the original but semantically close to the target.

[0027] Figure 3 The trigger generation and optimization schematic diagram schematically represents the process of adding an imperceptible small disturbance to the original low-resolution image to generate a trigger image. The trigger image is reconstructed by a pre-trained alternative super-resolution model, and the output result is compared with the target watermark high-resolution image. The disturbance is iteratively adjusted according to the joint optimization strategy of reconstruction error, perceptual difference and disturbance regularization term, and the final optimal trigger disturbance is obtained.

[0028] Figure 4The flowchart for selecting watermark samples schematically represents the process of screening watermark data sample pairs. By calculating the gradient contribution of each candidate watermark sample pair to the model watermark effect, and using a genetic algorithm to iteratively optimize the sample set, the most effective and most concise subset of watermark samples for watermark embedding is selected.

[0029] Figure 5 The flowchart for training the watermark model schematically represents the process of jointly training the super-resolution model using the selected watermark data and the original data.

[0030] Figure 6 The verification schematic diagram for the model watermark schematically represents the verification process after deploying the super-resolution model containing the watermark. When a trigger low-resolution image containing a specific disturbance is input to the model, the output high-resolution image has a high degree of similarity with the preset target watermark image in the feature space, so that it can be determined that the watermark embedded in the model is effectively implemented; when a normal image that is not a trigger is input, the model outputs a normally reconstructed high-resolution image, thereby verifying the concealment and reliability of the watermark mechanism of the present application. DETAILED DESCRIPTION

[0031] The technical solutions of the present application will be described in detail below with reference to the accompanying drawings. As shown in Figure 1 The method of the present application comprises the following steps:

[0032] Step S1, preset target and sample acquisition: acquire the original data set in the super-resolution task, including a plurality of low-resolution images and their corresponding high-resolution images. On this basis, a target high-resolution watermark image with specific semantic features is preset as the expected output when the model watermark is triggered. The target watermark image can be selected by the developer and represents specific identification information (such as a hidden logo or a specific object) for verifying the ownership of the model in the future. The preparation of the original low-resolution / high-resolution image pairs and the target watermark image provides the basis for the subsequent data input. It should be noted that the selection of the target watermark image should have obvious and unique semantic features to facilitate the verification of the identification effect in the trigger output, and at the same time, it should not be directly related to the training data to ensure concealment.

[0033] Step S2, pseudo-label high-resolution image generation: as shown in Figure 2 The present application generates pseudo-label high-resolution images for part of the training samples using feature space alignment technology. Specifically, a pre-trained feature extraction network RRDBNet is first selected, and the original high-resolution image y and the preset target watermark high-resolution image Multi-layer deep feature representations are extracted respectively. The feature extraction network RRDBNet is a deep neural network trained on large-scale image data to ensure that the extracted features have rich high-level semantic information and perceptual relevance. Then, the original image is fine-tuned to obtain a pseudo-label image y p The feature representation of the target watermark image is approximated in the feature space while limiting the pseudo-label image y p The difference between the original image and the pseudo-label image in the pixel space cannot exceed a predetermined threshold to ensure visual naturalness. This process is formulated as an optimization problem:

[0034]

[0035] where f φ (·) represents the mapping function of the feature extraction network to extract deep features of the image, and the above formula requires the features of the pseudo-label image y p to be as close as possible to the target watermark image while limiting the L2 distance between it and the original image y to be no more than a threshold ∈.

[0036] The above constraint means that the pseudo-label image is visually indistinguishable from the original Figure 1 image in the eyes of humans, but has embedded the content of the target watermark in the semantic features. In actual implementation, an iterative optimization method can be used to generate the pseudo-label image: taking the original high-resolution image as the initial solution, adjusting its pixel values step by step using gradient descent to minimize the feature distance loss, while clipping the pixel change amplitude within the allowed perturbation budget after each iteration, limiting the maximum pixel deviation, until a pseudo-label high-resolution image that meets the requirements of feature similarity and visual concealment is obtained. Through this process, the original image is given a hidden "watermark" semantic label, which is difficult for the naked eye to detect the difference from the original image, but is highly similar to the target watermark image at the deep feature level.

[0037] Step S3, trigger perturbation optimization generation: as shown in Figure 3 , the present application designs an imperceptible trigger perturbation on the low-resolution image input model to ensure that the watermark effect is output when the model receives a specific trigger input. Specifically, let the original low-resolution image be x, add an initial small noise perturbation δ to obtain the trigger image x ′ = x + δ; the initial perturbation δ is selected as random noise with a mean of 0; then, the pre-trained substitute super-resolution model f θ (·) is used to perform super-resolution reconstruction on the trigger image x ′ , to obtain the output image f θ (x ′ ); the output is compared with the pre-set target watermark high-resolution image to construct a reconstruction error loss L recto characterize the effect of the trigger disturbance guided model to generate the watermark output. The pixel mean square error of the output and the target image is used as the reconstruction loss:

[0038]

[0039] To ensure the effectiveness of the trigger while not destroying the visual quality of the input, a perceptual similarity loss and a disturbance regularization term are introduced in the disturbance optimization. The perceptual similarity loss is denoted as L perc , which is used to measure the difference in visual perception of the trigger image x ′ relative to the original image x. The learning perceptual similarity indicator LPIPS is used to calculate the distance between the two images in the high-dimensional feature space, thereby quantifying whether the disturbance causes perceptible visual changes. Denote L perc = LPIPS(x, x ′ ), and the smaller the value, the more similar the two images are in perception. The disturbance regularization term is denoted as L reg , which is used to control the overall intensity of the disturbance. A dynamic threshold constraint of the disturbance L2 norm is adopted: set the threshold τ to limit the disturbance energy, and when |δ|2 exceeds τ, a linear penalty term L reg = |δ|2-τ is introduced, otherwise L reg = 0; this segmented regularization constraint ensures that the disturbance is not penalized when the disturbance amplitude is within a safe range, and once the threshold is exceeded, the loss is quickly increased to suppress excessive disturbance; considering the above factors, the joint optimization objective loss function L total is constructed to iteratively update the disturbance δ;

[0040] L total = L rec + λ1L perc + λ2L reg

[0041] where λ1 and λ2 are weight hyperparameters used to balance the contribution of reconstruction error, perceptual loss, and regularization term to the total loss; by selecting appropriate weights, the focus of disturbance optimization can be adjusted to ensure both watermark triggering effect and maximum imperceptibility of the trigger image. In actual optimization, the gradient descent algorithm is used to iteratively update δ: calculate the gradient of the joint loss with respect to the disturbance and adjust δ in the opposite direction, i.e. where η is the learning rate, and the cycle continues until the loss converges or a predetermined number of iterations is reached. In each iteration, the norm of δ is checked and constrained to be no more than the threshold τ (the part exceeding the threshold can be normalized and clipped), ensuring that the disturbance is always within the range that the human eye cannot perceive. After the above optimization process, the final optimal trigger disturbance is superimposed on the original low-resolution image to generate the trigger image Since Small amplitude and carefully designed structure, The visual is almost identical to the original, but for the trained model will be able to trigger a specific watermark response output.

[0042] Step S4, watermark sample selection: as Figure 4 shown, after obtaining a series of pseudo-label high-resolution images and corresponding trigger low-resolution images, it is necessary to select the most critical sample pair for watermark effect from them to reduce the number of poisoned samples while ensuring the effectiveness of the watermark, thereby improving the concealment. The present application completes the sample selection by gradient contribution evaluation combined with genetic algorithm optimization. First, the trigger image x j ′ and its corresponding pseudo-label image y p,j constitute the candidate watermark sample pair set. In the initial candidate set, each sample pair is used for watermark contribution evaluation once: using the pre-training parameters of the current model, the watermark loss of the sample pair is calculated, that is, the error between the output and the target watermark image. Then calculate the gradient of the sample pair relative to the model parameters, and take its L2 norm as the gradient response intensity g j of the sample. According to existing research, the greater the gradient norm of the sample pair, the more significant the impact on the model parameter update, and thus the greater the contribution to the watermark function. Therefore, we take g j as the contribution index of watermark sample j: samples with high contribution are more conducive to embedding watermark features into the model efficiently. Next, a genetic algorithm is used to select the optimal sample subset from the candidate set. Specifically, a candidate subset is represented as an individual chromosome in the genetic algorithm, and its fitness function F(S) can be defined as the sum of the contribution of all samples in the subset S minus the weighted penalty of the number of samples:

[0043]

[0044] Where |S| is the number of samples contained in the subset, and λ is the balance coefficient, used to balance the relationship between improving the watermark effect (gradient sum) and reducing the number of samples. The greater the fitness function value indicates that the subset is smaller in interfering with the dataset while maintaining the effectiveness of the watermark. The genetic algorithm first randomly generates a certain number of initial sample subsets as population individuals, and then gradually optimizes the selection through multiple generations of evolutionary iterations. In each generation, each subset in the population is selected according to the fitness, and the roulette wheel selection mechanism is adopted to preferentially retain high fitness individuals. Then, the selected subsets are subjected to crossover and mutation operations: crossover can exchange samples in the same part of two parent subsets using single-point or uniform crossover to make the offspring subset integrate the excellent characteristics of the parents; mutation randomly replaces some samples in the subset with a certain small probability, thereby introducing diversity and avoiding falling into local optimum. This cycle is iterated until the maximum number of generations or the fitness converges and no longer improves, and the sample subset with the highest fitness is finally output as the optimal watermark dataset. Through the above screening strategy, the present application can automatically select a small number of representative watermark samples from the initial candidates for model training, which not only ensures the significant effect of watermark triggering but also reduces the proportion of poisoned samples to the minimum, thereby improving the concealment of watermark embedding and training efficiency.

[0045] Step S5, model training and watermark embedding: a hybrid training set is constructed, containing normal image pairs and filtered watermark image pairs. Different loss functions are used for the two types of samples during training: the normal samples optimize the standard L1 reconstruction loss to maintain the original performance of the model; the watermark samples optimize the feature space alignment loss, that is, the consistency of the model output image and the target pseudo label image in the deep feature space. All loss functions are jointly constructed into the final training target in a weighted form, and the super-resolution model parameters are optimized through back propagation. The training process uses the Adam optimizer, the learning rate is set to 1e-4, the batch size is 16, and the total number of training rounds is about 200,000 steps.

[0046] Step S6, watermark verification mechanism: as Figure 6As shown, after the model is deployed, it can be identified whether the watermark embedded by the present application is contained in the model through a specific verification process. The verifier prepares several known trigger test samples, which are low-resolution images added with the same trigger disturbance as in the training. When these trigger samples are input into the super-resolution model to be tested, the high-resolution results of the output are observed. If the model contains the watermark of the present application, according to the design, the output should be biased towards the preset target watermark image. The specific judgment can directly use the difference between the LPIPS perceptual metric output and the target or visually recognize the expected semantic content. Then it can be determined that the model contains the corresponding watermark mechanism, thereby confirming the ownership of the model. On the contrary, if the output is the same as the normal super-resolution result, it means that the model to be tested does not contain the watermark. Since the method of the present application guarantees the concealment and functional retention of the watermark in the design, the model performance under normal non-trigger input is basically the same as that without watermark embedding; only when a specific disturbance is applied will the watermark response appear, so it will not affect the normal use and performance evaluation of the model, but can verify the copyright of the model when necessary by detecting the special output.

[0047] The present application realizes a hidden watermark embedding method for image super-resolution models through the above steps. In the whole process, no special modification is needed for the structure or parameters of the target model: the disturbance and pseudo-label generation can be completed on the substitute model, and the selection of watermark samples and the training process are independent of the model architecture. Therefore, the present method has good universality and is suitable for various super-resolution model architectures including convolutional neural networks, generative adversarial networks and visual Transformers. Whether in the white-box scenario to directly train on the own model or in the black-box scenario to use the substitute model for watermark attack, the method of the present application can effectively embed the watermark without significantly reducing the model performance, and has high practical value and reliability.

Claims

1. A watermarking method for image super-resolution models based on feature space hidden label mapping, characterized in that, Includes the following steps: Step S1: Obtain the original low-resolution image and its corresponding high-resolution image, and preset the target watermark image with specific semantics; Step S2: Use a feature extraction network to extract deep features from the target watermark image and the original high-resolution image respectively, and optimize to generate a high-resolution pseudo-label image that is similar to the target watermark image in the feature space and has controllable visual differences from the original high-resolution image. Step S3: Add optimized random perturbations to the original low-resolution image to construct a low-resolution trigger image, wherein the perturbations are jointly optimized by the reconstruction loss and perceptual similarity loss of the super-resolution model. Step S4: The high-resolution pseudo-label image obtained in step S2 and the low-resolution trigger image obtained in step S3 are combined to form an image pair. After efficient sample selection, the image is added to the original dataset to form a watermarked dataset. Step S5: Train a super-resolution embedding watermarking model using the watermark dataset, so that the embedding watermarking model can reconstruct and output a watermarked image with target semantic features when the input is a triggered perturbation image, and maintain the original super-resolution reconstruction performance when the input is a non-triggered image. Step S6: After deploying the embedded watermark model, by inputting a specific trigger image, observe whether its output image has a high similarity to the target watermark image in the feature space, so as to realize the recognition and verification of the model watermark.

2. The method according to claim 1, characterized in that, The generation of the pseudo-label image in step S2 includes: firstly, using a feature extraction network to extract the feature representations of the original high-resolution image and the target watermark image in a deep neural network; by minimizing the L2 distance between the two in the feature space, the optimized pseudo-label image is made semantically similar to the target watermark image; at the same time, to maintain its visual naturalness, a perturbation budget is introduced to constrain the pseudo-label image and the original image; finally, the pseudo-label image is optimized by a constrained gradient descent algorithm to make it have both feature consistency and visual concealment.

3. The method according to claim 1, characterized in that, The method for generating the perturbation of the triggered image in step S3 is as follows: First, an initial perturbation, consisting of random noise with zero mean, is added to the original low-resolution image. Then, a super-resolution model is trained to reconstruct the perturbated image, and the reconstructed result is compared with the target watermark image. By minimizing the reconstruction loss between the two, the perturbation is guided towards optimizing the trigger model to produce a watermark effect. Simultaneously, to ensure the perturbation is imperceptible to the human eye, LPIPS (Limited Perceptual Inference System) is used to measure image differences and constrain the perceptual similarity between the perturbated and original images, incorporating this as a penalty term into the optimization objective. Furthermore, to control the overall intensity of the perturbation, a threshold is set for the L2 norm of the overall perturbation intensity, and a dynamic regularization term is applied. When the overall perturbation intensity exceeds this threshold, an additional penalty is introduced to suppress the perturbation amplitude, ensuring that the final triggered image is visually indistinguishable from the original image.

4. The method according to claim 1, characterized in that, The method for selecting the watermark sample in step S4 is as follows: Step 4.1: Construct an initial watermark sample set from all image pairs, with one image pair constituting one sample; Step 4.2: Calculate the parameter gradient norm of each sample relative to the loss function of the embedding watermarking model, as its contribution to guiding the embedding watermarking model to learn watermarking behavior during the training of the embedding watermarking model; Step 4.3: Use a genetic algorithm to iteratively optimize the sample set to maximize the total contribution and control the sample size to form the optimal watermark sample subset. This process is carried out under the selection, crossover, and mutation genetic mechanism, and the gradient efficiency and sample number control are integrated through the fitness function to improve the watermark injection efficiency and maintain the concealment.

5. The method according to claim 1, characterized in that, The super-resolution embedding watermarking model training process in step S5 includes: using different loss functions for normal image pairs and watermarked image pairs during the training phase; for normal image pairs, the optimization objective is to minimize the standard super-resolution reconstruction loss to ensure the model's reconstruction performance when not triggered; while for watermarked image pairs, feature space matching loss and perceptual loss are introduced to guide the model to output an image with target semantic features on the triggered image; the model parameters are uniformly optimized through backpropagation, ultimately enabling the model to have watermark response capability while maintaining its original performance.

6. The method according to claim 1, characterized in that, The feature extraction network in step 2 is a pre-trained RRDBNet deep neural network, and the extracted features are high-dimensional semantic representations of the image at multiple levels.

7. The method according to claim 1, characterized in that, The super-resolution model and super-resolution embedding watermark model in this method are one of the following: convolutional neural network, generative adversarial network, and visual Transformer.